Healthcare Software Infrastructure Migration to a Private Cloud
Software modernization allowing a US-based healthcare provider to strengthen the system’s HIPAA compliance and reduce its run rate by roughly 30%
ABOUT the project
- Client:
- Provider of Healthcare SaaS Solutions
- Location:
-
USA
- Company Size:
- 50+ Employees
- Industry:
-
Healthtech
- Solution:
-
Cloud Software Development
Technologies:
The Leobit team helped the customer migrate its electronic health records (EHR) platform from Azure to a dedicated private cloud environment provided by a HIPAA-certified US vendor. This allowed them to cut long-term infrastructure costs while strengthening HIPAA compliance. The solution involved a phased migration of compute, storage, and compliance tooling, with minimal downtime for the ~30 clinics relying on the platform daily.
We were really impressed with Leobit’s flexibility. Whenever new challenges came up, the team quickly found a practical way to handle everything, just like in the case with network interruptions during the migration. Solving these issues added very little to the project timeline, but made a big difference to our solution’s security and compliance.
Customer
Our customer is a mid-sized healthcare SaaS company managing electronic health records for a network of approximately 30 regional clinics. The platform handles patient records, appointment scheduling, and billing information for a steady, predictable volume of daily users. The customer doesn’t experience seasonal spikes or unpredictable demand, just steady business-hours traffic, five days a week, year-round.
Business Challenge
The customer built its EHR platform on Azure, expecting to expand by adding new clinics over time. That expansion never happened. The workload stayed almost the same, but cloud costs kept increasing.
After a new CTO joined the company, infrastructure spending became one of the first areas under review. Several audits showed that, for a stable workload like this, Azure would cost roughly 30–35% more than dedicated infrastructure. There was also another factor. Healthcare regulations required patient records to be stored for years, so storage requirements kept growing. Encryption, audit logging, and access controls added to the monthly bill.
At the same time, the platform barely benefited from the cloud’s ability to scale because patient volumes changed very little. The company decided to move to dedicated infrastructure to reduce costs without compromising security or compliance. The migration also had to be handled carefully, with no errors, downtime, or loss of sensitive medical data.
Why Leobit
Leobit’s team combines deep Azure expertise with industry-specific experience. We prepared a detailed proposal for a hybrid architecture, designed with healthcare security and compliance in mind, that aligned with the client’s business goals.
Project
in detail
The Leobit team handled the migration in several consecutive stages. We were primarily focused on data integrity, compliance continuity, and zero-downtime cutover.
Project in detail
Our specialists planned the target architecture with a strong focus on HIPAA compliance and security. In particular, we designed dedicated encryption key management, centralized audit logging, and role-based access controls built to run natively on private infrastructure rather than relying on Azure’s shared-tenancy compliance tooling. Upon planning the target architecture, we proceeded with the migration.
The sheer volume of data accumulated over years of operation put sustained pressure on the site-to-site connection. On several occasions, temporary network interruptions disrupted large transfer batches. Checksum validation detected the incomplete transfers, preventing any partial data from being committed.
To make the migration more resilient, our team introduced checkpointing and resumable transfer logic. Instead of restarting an interrupted batch from the beginning, the system resumed from the last verified record. This enhancement added a few days to the project, but it also eliminated repeated full-batch transfers and helped keep the overall migration on track.
While migrating patient data, we put strong focus on a phased approach instead of a single cutover. All records were migrated in batches. We validated these batches against checksums and access logs before the source data was decommissioned. This helped our specialists ensure that no records were lost, duplicated, or exposed during transfer.
Throughout the migration, our team ran continuous compliance and performance testing to confirm that HIPAA obligations were met at every stage. When the migration was complete, we ran full data validation, load testing, and a mock compliance audit before handoff.
Predictable Costs for a Predictable Workload
By separating fixed, steady-state processing from genuinely elastic services, we gave the customer an infrastructure model that finally matched their actual usage pattern. Instead of paying premium on-demand pricing for a workload that never demanded it, they got an opportunity to manage their costs more efficiently.
Effective Hybrid Infrastructure
We built a hybrid infrastructure where core EHR processing, long-term data storage, and compliance-related components were moved to new infrastructure hosted in the private cloud, running on VMware vSphere for virtualization. The application layer itself required no rewrite: .NET Core carried over unchanged, and data moved to Microsoft SQL Server on dedicated VMs.
Meanwhile, external dashboards and integrations remained in the public cloud, where they could still scale when needed. This approach helped the customer reduce infrastructure costs while keeping cloud flexibility where it actually mattered.
A Compliance Layer Built for Private Infrastructure
We migrated identity and access management from Azure AD to Windows Server AD, while encryption key management moved to HashiCorp Vault. Audit logging and alerting run on the Elastic Stack paired with Grafana, and backups are now handled through Veeam.
This improved compliance level gave the customer direct, demonstrable control over where patient data lives and who can access it. It also ensured that every suspicious attempt to reach sensitive data would trigger alerts. In combination with the updated access policies, this security layer sufficiently strengthened the application in terms of HIPAA compliance.
The Journey
Behind Our Success
Technology Solutions
- Innovative compliance layer using Windows Server AD, HashiCorp Vault, as well as Elastic Stack and Grafana for access control, encryption, and alerting, respectively.
- Hybrid infrastructure with sensitive data and static workflows are hosted in the private cloud.
- Checkpointing and resumable transfer logic introduced for improved migration resilience.
- Phased migration conducted in batches, with each batch going through a validation workflow.
Value Delivered
- The customer now runs its core EHR platform on cost-predictable, dedicated infrastructure instead of variable, usage-based Azure pricing.
- Compliance audits are simpler, with clear, centralized answers on data location, retention, and access.
- The migration reduced the system’s run rate by ~30% within the first year post-migration.
- The migration was completed without disruptions for end-customers’ operations.